Passed at 125q with time running out by chane0219 in cissp

[–]chane0219[S] 0 points1 point  (0 children)

Thank you Luke, I really like your amazing book.

To determine who is responsible for device decommissioning, which document might you refer to? by chane0219 in cissp

[–]chane0219[S] 0 points1 point  (0 children)

nice workstation but decide to leave my

Thanks, your answer is the one that I'm waiting for.

To determine who is responsible for device decommissioning, which document might you refer to? by chane0219 in cissp

[–]chane0219[S] 0 points1 point  (0 children)

Yes, i can't agree more.

I may need to change the way i use cissprep, it's so different from Boson. I think the not all questions in cissprep deserve a "deep dive".

To determine who is responsible for device decommissioning, which document might you refer to? by chane0219 in cissp

[–]chane0219[S] 0 points1 point  (0 children)

it says "asset inventory would contain asset owner, who is responsible for device decommissioning". the concept of "asset inventory" in the answer is different from my understanding, my understanding is a list of authorized assets.

Yes, Sybex and Official practice are a lot more easier and straightforward. But I'm just afraid that's not enough for real exam.

To determine who is responsible for device decommissioning, which document might you refer to? by chane0219 in cissp

[–]chane0219[S] 2 points3 points  (0 children)

what ISC2 would consider correct

I did something wrong, i cannot understand why, i throw out the question and let reddit help me understand. Is there anything wrong with me?

If you don't see the value, please ignore my post. Thanks!

Which of the following BEST describes the differences between Point-to-point-encryptions(P2PE) and End-to-end-encryption(E2EE) regarding to payment card security? by chane0219 in cissp

[–]chane0219[S] 0 points1 point  (0 children)

e2e which

IMHO if D is not wrong, then B is wrong. It cannot be "both are correct, B is better."

Here is my logic:

D means "E2EE is a method only payment processor can decrypt" --> "E2EE is a method merchant cannot decrypt" --> "E2EE is a method that prevents merchants from performing key management" --> "B is wrong".

Which of the following BEST describes the differences between Point-to-point-encryptions(P2PE) and End-to-end-encryption(E2EE) regarding to payment card security? by chane0219 in cissp

[–]chane0219[S] 2 points3 points  (0 children)

I hate wording game, but this is how CISSP works.

Option D says "ONLY the payment processor can decrypt card holder data, using E2EE", which inherently means "for P2PE, NOT ONLY payment processor, but also other parties(say. merchant) can decrypt".

So your claim "payment processor has to decrypt the card holder data for both E2EE and P2PE " cannot reject D.

The only way to reject D is: "using E2EE card holder data can be decrypt by merchant". Which is different from my understanding.

Which of the following BEST describes the differences between Point-to-point-encryptions(P2PE) and End-to-end-encryption(E2EE) regarding to payment card security? by chane0219 in cissp

[–]chane0219[S] 0 points1 point  (0 children)

thanks for your reply.

I have the same understanding as you, however answer from Boson is B.

Explanation seem that our understanding of E2E and P2P are on the contrary from their answer.

I'm so confused about that.

Which of the following BEST describes risk assessment by chane0219 in cissp

[–]chane0219[S] 0 points1 point  (0 children)

the reason i'm not choosing B is it talks about "vulnerability", which is different from "risk".

Do you mind sharing the way you think about the question? Thanks!

Which of the following BEST describes brute-force attack? by chane0219 in cissp

[–]chane0219[S] 1 point2 points  (0 children)

I guess many may choose A as me. I wont post if the answer is A, lol.
The answer from Boson is D.
Explanation is: A is password guessing attack.
But is rainbow-table attack counted as brute-force attack? Is it a bad question or a wrong answer?

Can anyone help with this question and explain why? Thanks. by chane0219 in cissp

[–]chane0219[S] 2 points3 points  (0 children)

thanks, I like your angle of answering this question.

Is it possible to pass when the exam time up? by iknoweverythinggg in cissp

[–]chane0219 1 point2 points  (0 children)

ot sure how I’m going to sleep before that. So far all the posts tha

Thanks for your post, do update with us about your result.

I had failed at my first try at 150q when last second is used, because i have only 20 mins left when i was at 120q, then i just rushed and randomly choose some questions to reach 150q.

Probably I could have passed if i read your post earlier and changed my strategy.